CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1272  CVE-1999-1292  Candidate  Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
1533  CVE-1999-1553  Candidate  Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
1535  CVE-1999-1555  Candidate  Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan"s antivirus update feature to install a Trojan horse dll.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> http://support.cai.com/Download/patches/inocnt.html  View
1030  CVE-1999-1050  Candidate  Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to "directory | traversal" and just mean .. problems; but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | "different." Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
3854  CVE-2001-1050  Candidate  CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.  Proposed (20020131)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green    View

Page 689 of 20943, showing 5 records out of 104715 total, starting on record 3441, ending on 3445

Actions